US11425137B2ActiveUtilityA1

Centralized authentication for granting access to online services

Assignee: AT & T IP I LPPriority: May 29, 2015Filed: May 29, 2020Granted: Aug 23, 2022
Est. expiryMay 29, 2035(~8.9 yrs left)· nominal 20-yr term from priority
Inventors:Dale W. Malik
H04W 12/63H04L 63/102H04W 4/02H04L 63/107H04L 63/08H04W 12/08H04W 12/06
71
PatentIndex Score
0
Cited by
98
References
20
Claims

Abstract

Methods, apparatus, systems and articles of manufacture to implement centralized authentication for granting access to services are disclosed. Example apparatus disclosed herein to perform device authentication at a first service are to access a profile based on an identification code included in an authentication request from a second service, the profile corresponding to a device associated with the identification code, the identification code assigned to the device by the first service. Disclosed example apparatus are also to assign a selected one of a plurality of trust levels to the device based on activity information associated with the device, location information specified for the device in the profile, and mobility information specified for the device in the profile. Disclosed example apparatus are further to transmit authentication information for the device to the second service responsive to the authentication request, the authentication information including the selected one of the trust levels.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
       1. An apparatus to perform device authentication, the apparatus comprising:
 memory; and 
 at least one processor associated with a first service, the at least one processor to execute computer readable instructions to at least:
 access a profile based on an identification code included in an authentication request from a second service different from the first service, the profile corresponding to a device associated with the identification code, the identification code assigned to the device by the first service; 
 assign a selected one of a plurality of trust levels to the device based on (i) activity information associated with the device, (ii) location information specified for the device in the profile, and (iii) mobility information specified for the device in the profile; and 
 transmit authentication information for the device to the second service responsive to the authentication request, the authentication information including the selected one of the plurality of trust levels. 
 
 
     
     
       2. The apparatus of  claim 1 , wherein the location information identifies an expected location of the device, and the mobility information specifies whether the device is mobile. 
     
     
       3. The apparatus of  claim 2 , wherein the activity information includes a location of the device, and the at least one processor is to assign the selected one of the plurality of trust levels to the device by at least:
 obtaining the location of the device; 
 comparing the location of the device to the expected location; 
 assigning a first one of the plurality of trust levels to the device when (i) the location of the device does not correspond to the expected location and (ii) the mobility information specifies that the device is mobile; and 
 assigning a second one of the plurality of trust levels to the device when (i) the location of the device does not correspond to the expected location and (ii) the mobility information specifies that the device is not mobile, the second one of the plurality of trust levels different from the first one of the plurality of trust levels. 
 
     
     
       4. The apparatus of  claim 3 , wherein the expected location corresponds to a home location. 
     
     
       5. The apparatus of  claim 3 , wherein the at least one processor is to assign a third one of the plurality of trust levels to the device when the location of the device corresponds to the expected location, the third one of the plurality of trust levels different from the first one of the plurality of trust levels and different from the second one of the plurality of trust levels. 
     
     
       6. The apparatus of  claim 3 , wherein the at least one processor is to at least one of access an activity log maintained for the device to obtain the location of the device, or query the device to obtain the location of the device. 
     
     
       7. The apparatus of  claim 1 , wherein the at least one processor is to:
 cause the device to present a registration interface in response to a registration request from the device; 
 obtain the location information and the mobility information from the device via the registration interface; and 
 store the location information and the mobility information in the profile. 
 
     
     
       8. A non-transitory computer readable medium comprising computer readable instructions that, when executed, cause at least one processor associated with a first service to at least:
 access a profile based on an identification code included in an authentication request from a second service different from the first service, the profile corresponding to a device associated with the identification code, the identification code assigned to the device by the first service; 
 assign a selected one of a plurality of trust levels to the device based on (i) activity information associated with the device, (ii) location information specified for the device in the profile, and (iii) mobility information specified for the device in the profile; and 
 transmit authentication information for the device to the second service responsive to the authentication request, the authentication information including the selected one of the plurality of trust levels. 
 
     
     
       9. The non-transitory computer readable medium of  claim 8 , wherein the location information identifies an expected location of the device, and the mobility information specifies whether the device is mobile. 
     
     
       10. The non-transitory computer readable medium of  claim 9 , wherein the activity information includes a location of the device, and the computer readable instructions cause the at least one processor to assign the selected one of the plurality of trust levels to the device by at least:
 obtaining the location of the device; 
 comparing the location of the device to the expected location; 
 assigning a first one of the plurality of trust levels to the device when (i) the location of the device does not correspond to the expected location and (ii) the mobility information specifies that the device is mobile; and 
 assigning a second one of the plurality of trust levels to the device when (i) the location of the device does not correspond to the expected location and (ii) the mobility information specifies that the device is not mobile, the second one of the plurality of trust levels different from the first one of the plurality of trust levels. 
 
     
     
       11. The non-transitory computer readable medium of  claim 10 , wherein the expected location corresponds to a home location. 
     
     
       12. The non-transitory computer readable medium of  claim 10 , wherein the computer readable instructions cause the at least one processor to assign a third one of the plurality of trust levels to the device when the location of the device corresponds to the expected location, the third one of the plurality of trust levels different from the first one of the plurality of trust levels and different from the second one of the plurality of trust levels. 
     
     
       13. The non-transitory computer readable medium of  claim 10 , wherein the computer readable instructions cause the at least one processor to at least one of access an activity log maintained for the device to obtain the location of the device, or query the device to obtain the location of the device. 
     
     
       14. The non-transitory computer readable medium of  claim 8 , wherein the computer readable instructions cause the at least one processor to:
 cause the device to present a registration interface in response to a registration request from the device; 
 obtain the location information and the mobility information from the device via the registration interface; and 
 store the location information and the mobility information in the profile. 
 
     
     
       15. A method to perform device authentication, the method comprising:
 accessing, by executing an instruction with at least one processor of a first service, a profile based on an identification code included in an authentication request from a second service different from the first service, the profile corresponding to a device associated with the identification code, the identification code assigned to the device by the first service; 
 assigning, by executing an instruction with the at least one processor, a selected one of a plurality of trust levels to the device based on (i) activity information associated with the device, (ii) location information specified for the device in the profile, and (iii) mobility information specified for the device in the profile; and 
 transmitting authentication information for the device to the second service responsive to the authentication request, the authentication information including the selected one of the plurality of trust levels. 
 
     
     
       16. The method of  claim 15 , wherein the location information identifies an expected location of the device, and the mobility information specifies whether the device is mobile. 
     
     
       17. The method of  claim 16 , wherein the activity information includes a location of the device, and the assigning includes:
 obtaining the location of the device; 
 comparing the location of the device to the expected location; 
 assigning a first one of the plurality of trust levels to the device when (i) the location of the device does not correspond to the expected location and (ii) the mobility information specifies that the device is mobile; and 
 assigning a second one of the plurality of trust levels to the device when (i) the location of the device does not correspond to the expected location and (ii) the mobility information specifies that the device is not mobile, the second one of the plurality of trust levels different from the first one of the plurality of trust levels. 
 
     
     
       18. The method of  claim 17 , wherein the assigning includes assigning a third one of the plurality of trust levels to the device when the location of the device corresponds to the expected location, the third one of the plurality of trust levels different from the first one of the plurality of trust levels and different from the second one of the plurality of trust levels. 
     
     
       19. The method of  claim 17 , further including at least one of accessing an activity log maintained for the device to obtain the location of the device, or querying the device to obtain the location of the device. 
     
     
       20. The method of  claim 15 , further including:
 causing the device to present a registration interface in response to a registration request from the device; 
 obtaining the location information and the mobility information from the device via the registration interface; and 
 storing the location information and the mobility information in the profile.

Join the waitlist — get patent alerts

Track US11425137B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.